The LiteLLM breach exposed 434,000 CI/CD pipelines, and the weak link was a vulnerability scanner
On August 11, 2026, CloudSEK put numbers on the LiteLLM compromise: 2,500 organizations and 434,000 CI/CD pipelines potentially exposed, through a compromised Trivy build that poisoned versions 1.82.7 and 1.82.8 on PyPI. The lesson for platform teams comes down to three decisions: pin, scope, and treat CI as an attack surface.